First published: Thu Mar 12 2020(Updated: )
XSS was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress via the rm_form_id, rm_tr, or form_name parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Metagauss Registrationmagic | =4.6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-8436 is medium, with a severity value of 6.1.
CVE-2020-8436 refers to a Cross-Site Scripting (XSS) vulnerability discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress.
The RegistrationMagic plugin version 4.6.0.0 for WordPress is affected by CVE-2020-8436.
The vulnerability can be exploited by manipulating the rm_form_id, rm_tr, or form_name parameter in the RegistrationMagic plugin for WordPress.
At this time, it is recommended to update to the latest version of the RegistrationMagic plugin for WordPress to mitigate the XSS vulnerability.